Version 2026.6 of this document takes effect on 13 October 2026, and until then the version in force applies. See the version in force
Cookie Policy
Effective 13 October 2026
Contents
1. Cookies and other storage
2. The banner and your choice
3. Essential items
4. Analytics
5. Advertising
6. Items for the website's features
7. Services that store nothing on your device
8. How to change your choice
9. The Strehana app
10. Questions
This page describes what Strehana stores on your device: the cookies and other browser storage when you use the website, and the data the app keeps on your phone. Strehana is operated by Vizium OOD. What we do with data on our servers, who we share it with and what rights you have is described in the «Privacy Policy» (strehana.com/en/privacy).
1. Cookies and other storage
A cookie is a small text file that a website stores in your browser and reads on your later visits. The browser has other places to store things too: local storage (localStorage), tab storage (sessionStorage), which is cleared when you close the tab, and a database in the browser (IndexedDB). Here we describe all of them together and call them storage items.
Most storage items are written by our website. Some are written by third-party code that we load: Google, Stripe and Meta. For each item we say who writes it, why, and how long it is kept.
2. The banner and your choice
On your first visit the website shows a cookie banner. In it you decide separately for two categories: analytics and advertising. Both are off by default.
The buttons are «Accept All», «Decline All» and «Customize», where you switch each category on or off and press «Save Preferences».
Before you answer, the website loads nothing for analytics or advertising. It writes only the essential items in section 3 and the items for the website's features in section 6.
Your choice is kept in the browser and recorded on our server (section 3). The banner appears again when a new version of the Privacy Policy takes effect.
3. Essential items
These work without your permission, because without them the website cannot sign you in, protect your requests from abuse, remember your language and your cookie choice, or take a payment. You cannot switch them off in the banner.
Sign-in and security
- access_token: a cookie on api.strehana.com that our server writes when you sign in. It carries the access token for your account. Code on the page cannot read it. Valid for 15 minutes.
- refresh_token: a cookie on api.strehana.com that our server writes when you sign in. It renews your session without signing in again, and it is itself replaced on every renewal. Code on the page cannot read it. Valid for 30 days.
- csrf_token: a cookie on strehana.com and its subdomains that our server writes when you sign in. It holds a random value that the website sends with every change, so that another website cannot act on your behalf. Valid for 30 days.
- has_session: a cookie on strehana.com that the website writes when you sign in and deletes when you sign out. It holds only «1», so the website knows you have an open session. Valid for 30 days, like refresh_token, and renewed together with it, or until you sign out.
- user_id (local storage): your account id, which the website writes when you sign in so that pages load faster. Deleted when you sign out.
Language and cookie choice
- NEXT_LOCALE: a cookie on strehana.com that our server writes when a page loads, and the website writes when you change language. It keeps the website's language (bg or en). Deleted when you close the browser.
- harbor_consent_preferences (local storage): your choice in the banner (analytics yes or no, advertising yes or no) and the version of the Privacy Policy it was made under. Kept until you clear the website's data in your browser.
- harbor_consent_session_id (local storage): a random id written at your first answer to the banner. Our server uses it to record each of your answers, so that we can prove your choice. In the server record we keep the choice, the policy version, a hash of your IP address with a secret salt and details of your browser, and, if you are signed in, your account. Kept in the browser until you clear the website's data.
- strehana.consent_synced_user (local storage): which account your choice was last sent for. When you sign in, the website sends your choice once more to link it to your account. Kept until you clear the website's data in your browser.
Payment
When you open a payment page (for example featuring a listing or a card, boosting an application, and the page after payment), we load Stripe's code. It takes the payment and checks for fraud. Stripe does not load on any other page.
- __stripe_mid: a cookie on strehana.com from Stripe, a device id for fraud prevention. Valid for 1 year.
- __stripe_sid: a cookie on strehana.com from Stripe, a session id for fraud prevention. Valid for 30 minutes.
- m: a cookie on m.stripe.com from Stripe, for fraud prevention. Valid for about 400 days.
4. Analytics
These run only if you allow «Analytics Cookies». They tell us how the website is used and where visitors come from, so that we can improve it.
- Google Analytics (Google): we load it only after you allow it. It writes the cookies _ga and _ga_725VLSSR0M on strehana.com: a browser id and visit data. Google sets them for 2 years, and Chrome caps them at 400 days. When you are signed in, we also send Google Analytics your account id.
- PostHog (product analytics, in the EU): once you allow it, the website sends PostHog which pages you open and what you do on them. Before sign-in the events carry the id posthog_anon_id, after sign-in your account id.
- posthog_anon_id (local storage): a random browser id that the website writes when you allow analytics and replaces with a new one when you sign out. While the permission stands, the website also sends it to our server, to link the deck we show you with what you do in it. Kept until you clear the website's data or withdraw the analytics permission.
- harbor_first_use_features (local storage): a list of features already used in this browser, for example an opened conversation or a data download. The website writes it only after you allow analytics and deletes it when you withdraw. Its only use is a «first use» marker in events for Google Analytics.
- strehana_src: a cookie on strehana.com that the website writes when you allow analytics. It keeps where you came from on your first visit: the kind of source (paid search, paid social, referral from another website, organic or direct), the campaign parameters in the link (utm, gclid, fbclid), the website you came from, and the first page you opened. It is never overwritten. While the permission stands, the website sends the channel and the campaign to our server with your actions, so that we know where new accounts come from. Valid for 90 days.
Before you allow it, the website holds the source of the visit only in the page's memory and does not store it. If you decline, it forgets it.
Declining stops analytics in your browser. What our server counts without your account id is described in the Privacy Policy.
5. Advertising
These run only if you allow «Advertising Cookies». The website shows no ads. With these technologies we measure our own ads on Facebook and Instagram, which belong to Meta.
- The Meta pixel: we load it only after you allow it. It tells Meta which pages you open and some actions on the website, for example a viewed listing, a search, an application, a saved listing, a message, a new listing or card, a started payment and a payment. When you are signed in, it also sends your name, gender and account id, hashed.
- _fbp: a cookie on strehana.com written by the Meta pixel. Your browser's id for Meta. Valid for 90 days.
- _fbc: a cookie on strehana.com with the click id when you come from a Meta ad (the fbclid parameter in the link). We or the Meta pixel write it, only after you allow it; until then the id is only in the page's memory. Valid for 90 days.
- lastExternalReferrer and lastExternalReferrerTime (local storage): items the Meta pixel writes about the website the visit comes from, and when. Kept until you clear the website's data in your browser.
With the same permission, the website sends _fbp and _fbc to our server along with your actions, and our server sends Meta key actions, for example sign-up, a published listing or card, an application, a first message and a payment. If you allow advertising for the first time while signed in, within 7 days of signing up, we also send Meta your sign-up. What these messages contain is described in the Privacy Policy.
When both categories are allowed, we also tell Google Analytics that its advertising consent settings (ad_storage, ad_user_data, ad_personalization) are granted.
6. Items for the website's features
Our website writes these items in your browser so that the deck, drafts and some prompts work. They do not depend on the banner.
The deck
- strehana.deck.passed.v1 (local storage): the cards you passed, so they do not come straight back. Each pass is kept for 30 days, at most 500. The «See the ones you skipped» button clears them.
- strehana.deck.held.v1 (tab storage): likes made without an account, at most 3: the card, the first name of the person liked, the action and when. We send them once you sign in and then delete them. If you close the tab before that, they are lost.
Drafts and sign-in
- harbor_seeker_draft (local storage): a draft of a card started without an account: budget, places, openness to searching together, occupation, smoking, pets, move-in date and where it was started from. Kept for 7 days.
- harbor_seeker_draft_resume (tab storage): a marker that the card draft may publish itself after sign-in in the same tab.
- harbor_listing_draft (local storage): a draft of a room listing started without an account: every field filled in and the step. Kept for 7 days.
- harbor_draft_resume_publish (tab storage): a marker that the listing draft may publish itself after sign-in in the same tab.
- harbor_drafts (database in the browser): the photos of such a draft, until you publish or clear it. Drafts older than 7 days are deleted.
- harbor_signup_name (tab storage): your first name from signing in with Google or Apple, to fill in your profile. Deleted once used.
Prompts
- viewed_listings (local storage): up to 500 listings opened in this browser, so that we can mark them as viewed.
- strehana.applicant_profile_prompt (local storage): how many times we suggested completing your profile when you apply, so that it is not more than 2 times.
- strehana.notify_prompt_asked (local storage): whether we have already asked you about browser notifications.
- harbor_msg_safety_dismissed (local storage): whether the safety tips in «Inbox» have been closed.
- strehana.connection_strip_dismissed (local storage): whether the strip asking you to share Strehana in a new conversation has been closed.
The prompts are kept until you clear the website's data in your browser.
Items from older versions of the website
Older versions of the website wrote strehana_fbc (a Meta ad click id, up to 90 days), strehana_src and posthog_anon_id before the banner was answered. If your browser still has them, when you answer the website treats them like the new items: strehana_fbc becomes _fbc with the advertising permission and is otherwise deleted, and strehana_src and posthog_anon_id stay only with the analytics permission.
7. Services that store nothing on your device
The following services load without permission and store nothing on your device, but they see your IP address and the page they load from: the website's error reports (Sentry), on every page; the Google map, on pages with a map; Apple's sign-in library, wherever there is Sign in with Apple. Sign-in with Google opens in a separate Google window only when you press «Sign in with Google»; the cookies Google keeps in that window are on its own domain. More about them is in the Privacy Policy.
8. How to change your choice
- On the website, with or without an account: the «Cookie settings» link at the bottom of the page opens the banner again.
- If you are signed in: also from «Settings», section «Privacy & data», row «Cookie preferences», button «Manage cookies».
- In your browser: you can delete or block the website's cookies and other storage. If you delete the essential ones, you are signed out; if you block them, you cannot sign in.
What happens when you withdraw a permission
The page reloads so that scripts already loaded stop. After that, Google Analytics, PostHog and the Meta pixel do not load, and your new choice is recorded on our server.
When you withdraw the analytics permission, we delete strehana_src, posthog_anon_id, harbor_first_use_features and the Google Analytics cookies (_ga and _ga_725VLSSR0M). When you withdraw the advertising permission, we delete _fbp and _fbc and tell the Meta pixel that the permission is withdrawn.
Our server follows your latest choice: after a withdrawal, within a few minutes it stops sending Meta your actions and PostHog events with your account.
A withdrawal applies from then on. It does not affect the lawfulness of processing before it and does not delete data already sent. When you delete your account, we also delete your data in PostHog, and if you ever gave the advertising permission, we send Meta a signal that the account was deleted. Details are in the Privacy Policy.
9. The Strehana app
The Android and iOS app has no cookie banner. Instead it has one combined analytics choice.
After you sign in, the app asks you once whether to turn analytics on. The same choice turns on product analytics (PostHog) and sending key actions to Meta. It is off by default. Without an account the app does not ask and analytics stays off. You change the choice in «Settings», section «Privacy», row «Product analytics». When you sign out, analytics is switched off, and when the same account signs in again, its choice applies again.
Crash and error reports (Sentry and Firebase Crashlytics) are on by default and are not linked to your account. You stop them in «Settings», row «Share diagnostics», or without an account with «Stop the reports» on the sign-in screen.
What the app keeps on your phone
- Session: the access token, the refresh token and your account id, in the phone's secure storage (Android Keystore or iOS Keychain). Deleted when you sign out and when you delete your account.
- Your choices: whether analytics is on, for which account, under which version of the question and when, and whether crash reports are sent.
- On Android, after the analytics permission: a marker that the install source has already been read, and a Meta ad click id, if there is one. The id is valid for 90 days and is deleted when you switch analytics off.
- The deck: the passed cards, each for 30 days and at most 500, and up to 3 likes made without an account, which we send once you sign in.
- Drafts started without an account: of a card (budget, places, openness to searching together) and of a listing (role, location, rent, photo). Kept for 7 days.
- Unsent messages and hidden conversations.
- Up to 200 listings opened by your account. The app records them but does not use them yet.
- Prompts and counters: language, prompts and notification questions already shown, the app rating question, the feedback prompt and the oldest supported version.
- A temporary copy of your profile, listings, conversations and messages, applications, favourites, saved searches, notifications and payments, so the app opens faster. Deleted when you sign in and when you sign out. Separately, up to 100 MB of photos are kept.
- The file with the copy of your data, when you share it from the app. The app does not delete it; the phone may clear it.
- The Firebase libraries (for notifications and crash reports), Sentry, PostHog (only after the permission) and Sign in with Google on iOS keep their own ids and records.
When you sign out, the app deletes its items, except the choice about analytics and reports, the install source data, the app rating counters, the feedback prompt and, on older installs, the country code from a past phone check.
On Android the app's items are not included in the phone's backups. On iOS the app's settings file may be included in the phone's backup in iCloud or on a computer.
The app opens the terms, the policies, the imprint and the «How we order the cards» page in the phone's browser (Chrome Custom Tabs or Safari), in a view without the cookie banner. In that view we load no analytics and no advertising, whatever was chosen in the browser.
10. Questions
Write to us at legal@strehana.com.